Splunk Search

Splunk App for Anomaly Detection - "Could not load lookup=LOOKUP-HTTP_STATUS No matching fields exist."

danielbb
Motivator

In Step 2 "Add the Dataset" of "Create Anomaly Job" within the Splunk App for Anomaly Detection, when running the following SPL, we get the warning- 

 

 

 

index=wineventlog_security
| timechart count

"Could not load lookup=LOOKUP-HTTP_STATUS No matching fields exist."

 

 

 

 

What can it be?

We use the following versions -

Splunk App for Anomaly Detection - 1.1.0

Python for Scientific Computing  - 4.1.2 

Splunk Machine Learning Toolkit  - 5.4.0

Labels (1)
0 Karma

kcurtis
Splunk Employee
Splunk Employee

Can you confirm whether your original search returns > 0 events by running it in the search bar on the "Search" tab in AnomalyApp (or in Search & Reporting)?  This message may be shown because the search is returning 0 events.  We expect to have a fix for this, so our error message is more informative, in our next patch release of AnomalyApp.

0 Karma

danielbb
Motivator

@VatsalJaganiI looked in a couple of environments and I don't see it as automatic lookup. Any ideas?

0 Karma

VatsalJagani
SplunkTrust
SplunkTrust

@danielbb - What do you mean by a couple of environments? You need to check in the environment/SearchHead which is generating this error for you.

And there has to be automatic lookup. If you don't see it try to find it inside props.conf from the backend.

 

0 Karma

VatsalJagani
SplunkTrust
SplunkTrust

@danielbb - This automatic lookup could be present in any App.

You can try to find where it is present by going to Splunk UI > Lookups > Automatic lookups and select All App and Any Owner and filter for HTTP_STATUS and trying to find which App contains this lookup. You should be able to fix it from there as well.

 

I hope this helps!!!

Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...